Vulnerability Report: GO-2024-3306
- CVE-2024-53257, GHSA-7mwh-q3xm-qh6p
- Affects: vitess.io/vitess
- Published: Dec 12, 2024
Vitess allows HTML injection in /debug/querylogz and /debug/env in vitess.io/vitess
For detailed information about this vulnerability, visit https://github.com/vitessio/vitess/security/advisories/GHSA-7mwh-q3xm-qh6p.
Affected Packages
-
PathGo VersionsCustom Versions*Symbols
-
before v0.19.8, from v0.20.0 before v0.20.4, from v0.21.0 before v0.21.1before 19.0.8, from 20.0.0 before 20.0.4, from 21.0.0 before 21.0.1all symbols
-
before v0.19.8, from v0.20.0 before v0.20.4, from v0.21.0 before v0.21.1before 19.0.8, from 20.0.0 before 20.0.4, from 21.0.0 before 21.0.1all symbols
*Custom versions, which can't be mapped automatically to standard Go module versions, are ignored by govulncheck
. (See this note on versions for more details.)
Aliases
References
- https://github.com/vitessio/vitess/security/advisories/GHSA-7mwh-q3xm-qh6p
- https://github.com/vitessio/vitess/commit/2b71d1b5f8ca676beeab2875525003cd45096217
- https://vuln.go.dev/ID/GO-2024-3306.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.